VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise
2026-09-24T20:52:01Z•293a259af25af0a4a98c7c91f62a08bd7d968e93024ce2d8192ce3720bf7e6d3
CVE-2026-75907CVE-2026-82356CVE-2026-82987CVE-2026-82988CVE-2026-82989CVE-2026-86867CVE-2026-96775CVE-2026-96804CERT/CCMLflowOS-command-injectionRFID-cloningSecure-BootUEFIaccess-controlauthentication-bypassauthorization-bypasscruise-shipcryptographic-key-managementdevice-compromisehealthcaremultiple-vulnerabilitiespickle-deserializationprivilege-escalationremote-code-executionscreen-exfiltrationsmartboardsupply-chainunauthenticated-access
What happened
CERT/CC advisories describe multiple vulnerabilities disclosed September 16–24, 2026, including unauthenticated ViewSonic vCast screen capture and device compromise, RFID UID replay against Norwegian Cruise Line door controllers, non-rotatable Imprivata EAM RSA keys enabling appliance impersonation, cross-user conversation access in Kotaemon, Secure Boot bypass through vendor-signed UEFI Shell applications, root-level OS command injection in Dokploy, and MLflow pickle-deserialization control bypasses enabling code execution.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 293a259af25af0a4a98c7c91f62a08bd7d968e93024ce2d8192ce3720bf7e6d3
- Enrichment time
- 2026-09-24T20:52:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.